School Management System CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can submit malicious payloads using boolean-based blind SQL injection techniques to the processlogin endpoint to authenticate as administrator without valid credentials.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | School Management System CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can submit malicious payloads using boolean-based blind SQL injection techniques to the processlogin endpoint to authenticate as administrator without valid credentials. | |
| Title | School Management System CMS 1.0 Admin Login SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-26T13:02:45.335Z
Reserved: 2026-03-26T11:32:22.689Z
Link: CVE-2018-25201
Updated: 2026-03-26T13:00:57.364Z
Status : Received
Published: 2026-03-26T12:16:04.653
Modified: 2026-03-26T12:16:04.653
Link: CVE-2018-25201
No data.
OpenCVE Enrichment
Updated: 2026-03-26T13:54:47Z